Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
- ID
- 20266
- Status
- summarized
- Published
- 01 Sep 2026, 9:08 PM
- Fetched
- 01 Sep 2026, 10:56 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 01 Sep 2026, 10:58 PM
- Tags
- Audience
- developersvibe_coders
What happened
Iranian hacking group Nimbus Manticore is delivering cross-platform RATs (NodeRabbit and PollCat) by posing as recruiters on LinkedIn and sending developers trojanized coding challenge ZIP files. The malware, written in Node.js and obfuscated JavaScript, targets Linux and macOS systems and was first found on a machine in Afghanistan, with subsequent sightings in Egypt and Ethiopia. The attack ZIP ('Front-Technical-Challenge.zip') contains a fake project management tool called Taskflow and is hosted on AWS.
Why it matters
If you or your team receive coding challenges or technical assignments from recruiters via LinkedIn, verify the recruiter's identity through official company channels before downloading and running any ZIP archives. This attack specifically targets software engineers through a workflow they encounter routinely, and the malware is cross-platform—meaning macOS and Linux developers are not immune.
Discussion angle
How should teams handle take-home coding challenges from external recruiters—what's a practical verification protocol before running unknown code on your dev machine?